Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Add draft RFC for establishing CFF as a CVE Numbering Authority #762

Open
wants to merge 2 commits into
base: main
Choose a base branch
from
Open
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
22 changes: 22 additions & 0 deletions toc/rfc/rfc-draft-cff-cve-numbering-authority.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,22 @@
# Meta
[meta]: #meta
- Name: CFF CVE Numbering Authority
- Start Date: 2024-01-25
- Author(s): paulcwarren
- Status: Draft
- RFC Pull Request: https://github.com/cloudfoundry/community/pull/762


## Summary

For the last several years the CFF has relied on sponsoring member VMWare as the CVE numbering authority. When we have needed to publish a CVE, we claim a CVE number from their reservation block.

This responsibility should lie with the foundation itself.

## Problem

CVE must be published in a timely fashion. Any interruptions in the allocation of a CVE number, pre-disclosure or disclosure puts installations and their Users are at risk.

## Proposal

Establish Cloud Foundry Foundation as a CVE Numbering Authority managing its own block of CVE numbers.